44 CVEs published June 28, 2026: 1 critical, 8 high, 12 medium, 23 low; 0 in the KEV catalog at press time; 6 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 19 in the results table.
Yesterday's Results
How to read these box scores · glossary
44 CVEs published. 25 box scores, 19 table rows — nothing truncated.
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H P L N L L L 2.3 .0127 67.5 —
AFFECTED
Product Versions Fixed
Flowise unspecified 3.1.3
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
Nmap - Integer Underflow in IPv6 Extension Header Parsing
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L N L 6.9 .0088 56.3 —
AFFECTED
Product Versions Fixed
Nmap unspecified —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N L L H 8.3 .0071 50.6 —
AFFECTED
Product Versions Fixed
libssh2 unspecified —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N L N L L L 1.9 .0068 49.6 —
AFFECTED
Product Versions Fixed
ANTLR4 4.13.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L N N 5.5 .0055 43.7 —
AFFECTED
Product Versions Fixed
ANTLR4 4.13.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
joomcoder.com JoomCCK extension for Joomla — Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H N N 8.7 .0050 41.1 —
AFFECTED
Product Versions Fixed
JoomCCK extension for Joomla 1.0-6.4.0 – —
TIMELINE
May 27 Reserved by CNA
Jun 28 Published (CNA: Joomla)
Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0048 39.3 —
AFFECTED
Product Versions Fixed
JD12L 16.03.53.23 – —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulDB)
Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0047 38.6 —
AFFECTED
Product Versions Fixed
JD12L 16.03.53.23 – —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulDB)
libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N N L H 8.3 .0044 36.8 —
AFFECTED
Product Versions Fixed
libssh2 unspecified —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N N N L 2.9 .0041 34.5 —
AFFECTED
Product Versions Fixed
xiaozhi-esp32 2.2.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
zephyrproject zephyr — Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N U N H H 7.4 .0032 24.9 —
AFFECTED
Product Versions Fixed
zephyr 3.7.0 – —
TIMELINE
Jun 2 Reserved by CNA
Jun 28 Public exploit reference published
Jun 28 Published (CNA: zephyr)
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0031 23.9 —
AFFECTED
Product Versions Fixed
ANTLR4 4.13.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
glpi-project glpi Document document.send.php canViewFile authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N L N N 6.3 .0031 23.6 —
AFFECTED
Product Versions Fixed
glpi 11.0.5 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
n/a MLflow — MLflow Experiment-scoped Label Schema CRUD API authorization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N L N L L L 1.3 .0031 23.3 —
AFFECTED
Product Versions Fixed
MLflow 4666cffc7912ea606d592fc38d6a75e2935f65e7 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
n/a RAGapp — RAGapp Knowledge File files.py FileHandler.remove_file path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0029 22.0 —
AFFECTED
Product Versions Fixed
RAGapp 0.1.0 – —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulDB)
zephyrproject zephyr — Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
AV AC PR UI S C I A CVSS EPSS %ile KEV
A L N N U N N H 6.5 .0028 20.8 —
AFFECTED
Product Versions Fixed
zephyr 4.3.0 – —
TIMELINE
Jun 1 Reserved by CNA
Jun 28 Public exploit reference published
Jun 28 Published (CNA: zephyr)
yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P N L N 2.1 .0028 20.4 —
AFFECTED
Product Versions Fixed
restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L H 8.8 .0027 20.0 —
AFFECTED
Product Versions Fixed
FFmpeg unspecified —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
SourceCodester Class and Exam Timetabling System preview.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0027 19.1 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System preview6.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0027 19.1 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System archive.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0027 19.1 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
SourceCodester Class and Exam Timetabling System preview7.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0027 19.1 —
AFFECTED
Product Versions Fixed
Class and Exam Timetabling System 1.0 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0027 19.1 —
AFFECTED
Product Versions Fixed
restaurent-management-system 5f3eca87cb681366866a78038af17891c4c86612 – —
TIMELINE
Jun 27 Reserved by CNA
Jun 28 Published (CNA: VulDB)
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 9.4 .0027 18.6 —
AFFECTED
Product Versions Fixed
act_runner unspecified —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N L L N 6.3 .0026 18.3 —
AFFECTED
Product Versions Fixed
nghttp2 unspecified —
TIMELINE
Jun 28 Reserved by CNA
Jun 28 Published (CNA: VulnCheck)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-13493 | 1.3 | 14.3 | AIDC-AI | ComfyUI-Copilot | CWE-99 | AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resou… |
| CVE-2026-10644 | 3.1 | 14.0 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-… |
| CVE-2026-13489 | 1.3 | 13.8 | 78 | xiaozhi-esp32 | CWE-662 | 78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchroniza… |
| CVE-2026-13512 | 2.1 | 12.8 | n/a | Databend | CWE-285 | Databend Tenant client_session_manager.rs state_key authorization |
| CVE-2026-13511 | 1.3 | 12.8 | n/a | VoltAgent | CWE-266 | VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation impr… |
| CVE-2026-13510 | 2.9 | 12.3 | SimStudioAI | sim | CWE-327 | SimStudioAI sim Password Protection deployment.ts weak hash |
| CVE-2026-13495 | 2.0 | 12.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System adminprofile.php sql injection |
| CVE-2026-13496 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System ajaxmedicine.php sql injection |
| CVE-2026-13497 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System appointment.php sql injection |
| CVE-2026-13504 | 2.0 | 10.6 | code-projects | Project Management System | CWE-79 | code-projects Project Management System Mail Compose mail.php cross site scri… |
| CVE-2026-58056 | 7.2 | 9.2 | RustDesk | RustDesk | CWE-863 | RustDesk - FileTransfer Session Authorization Scope Bypass |
| CVE-2026-13482 | 2.9 | 8.9 | skypilot-org | skypilot | CWE-327 | skypilot-org skypilot User ID server.py username.encode weak hash |
| CVE-2026-13508 | 2.0 | 6.2 | khoj-ai | khoj | CWE-285 | khoj-ai khoj Conversation Sharing api_chat.py authorization |
| CVE-2026-13507 | 2.3 | 3.7 | volcengine | OpenViking | CWE-345 | volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_t… |
| CVE-2026-13513 | 1.3 | 3.3 | MyScale | MyScaleDB | CWE-345 | MyScale MyScaleDB SegmentId.h getCacheKey data authenticity |
| CVE-2026-13514 | 0.9 | 3.3 | Chess | Play and Learn App | CWE-285 | Chess Play and Learn App com.chess AndroidManifest.xml backup |
| CVE-2026-58052 | 4.8 | 2.0 | 7-Zip | 7-Zip | CWE-693 | 7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision |
| CVE-2026-13483 | 1.3 | 0.9 | arc53 | DocsGPT | CWE-345 | arc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authe… |
| CVE-2026-13502 | 1.1 | 0.6 | antlr | ANTLR4 | CWE-362 | antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObje… |
Methodology
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-28 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.